cbcvebase.
CVE-2025-2564
published 2025-04-16

CVE-2025-2564: Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to properly enforce the 'Allow users to view/update archived channels' System Console setting, which allows authenticated users to view members and member information of archived channels even when this setting is disabled.

Affected

13 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.4.0+incompatible < 10.4.4+incompatible10.4.4+incompatible
github.commattermost_mattermost-server>= 10.5.0+incompatible < 10.5.2+incompatible10.5.2+incompatible
github.commattermost_mattermost-server>= 9.11.0+incompatible < 9.11.10+incompatible9.11.10+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250314142426-c049748b88638.0.0-20250314142426-c049748b8863
github.commattermost_mattermost_server_v8>= 10.4.0 < 10.4.410.4.4
github.commattermost_mattermost_server_v8>= 10.5.0 < 10.5.210.5.2
github.commattermost_mattermost_server_v8>= 9.11.0 < 9.11.109.11.10
mattermostmattermost10.4.0 – 10.4.3
mattermostmattermost10.5.0 – 10.5.1
mattermostmattermost9.11.0 – 9.11.9
mattermostmattermost_server>= 10.4.0 < 10.4.410.4.4
mattermostmattermost_server>= 10.5.0 < 10.5.210.5.2
mattermostmattermost_server>= 9.11.0 < 9.11.109.11.10